Public-domain · open source
OpenJurist

N.C. Gen. Stat. § 143B-1320

Definitions; scope; exemptions

Redline — June 1, 2021 → current.View current text →
Current — June 1, 2022
As of June 1, 2021
(1) Definitions. - The following definitions apply in this Article: CGIA. - Center for Geographic Information and Analysis.
(1) Definitions. — The following definitions apply in this Article: CGIA. — Center for Geographic Information and Analysis.
(2) CJIN. - Criminal Justice Information Network.
(2) Repealed by Session Laws 2021-180, s. 19A.7A(d), effective January 1, 2022.
(3) Community of practice. - A collaboration of organizations with similar requirements, responsibilities, or interests.
(3) Community of practice. — A collaboration of organizations with similar requirements, responsibilities, or interests.
(4) Cooperative purchasing agreement. — An agreement between a vendor and one or more states or state agencies providing that the parties may collaboratively or collectively purchase information technology goods and services in order to increase economies of scale and reduce costs.
(4) Cooperative purchasing agreement. — An agreement between a vendor and one or more states or state agencies providing that the parties may collaboratively or collectively purchase information technology goods and services in order to increase economies of scale and reduce costs. (4a) Cybersecurity incident. — An occurrence that: Actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or
(5) Cybersecurity incident. - An occurrence that: Actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or
(6) Constitutes a violation or imminent threat of violation of law, security policies, privacy policies, security procedures, or acceptable use policies.
(5) Constitutes a violation or imminent threat of violation of law, security policies, privacy policies, security procedures, or acceptable use policies.
(7) Department. — The Department of Information Technology.
(6) Department. — The Department of Information Technology.
(8) Distributed information technology assets. — Hardware, software, and communications equipment not classified as traditional mainframe-based items, including personal computers, local area networks, servers, mobile computers, peripheral equipment, and other related hardware and software items.
(7) Distributed information technology assets. — Hardware, software, and communications equipment not classified as traditional mainframe-based items, including personal computers, local area networks, servers, mobile computers, peripheral equipment, and other related hardware and software items.
(9) Enterprise solution. — An information technology solution that can be used by multiple agencies.
(8) Enterprise solution. — An information technology solution that can be used by multiple agencies.
(10) Exempt agencies. — An entity designated as exempt in subsection (b) of this section.
(9) Exempt agencies. — An entity designated as exempt in subsection (b) of this section.
(11) GDAC. — Government Data Analytics Center.
(10) GDAC. — Government Data Analytics Center.
(12) GICC. — North Carolina Geographic Information Coordinating Council.
(11) GICC. — North Carolina Geographic Information Coordinating Council.
(13) Information technology or IT. — Set of tools, processes, and methodologies, including, but not limited to, coding and programming; data communications, data conversion, and data analysis; architecture; planning; storage and retrieval; systems analysis and design; systems control; mobile applications; and equipment and services employed to collect, process, and present information to support the operation of an organization. The term also includes office automation, multimedia, telecommunications, and any personnel and support personnel required for planning and operations.
(12) Information technology or IT. — Set of tools, processes, and methodologies, including, but not limited to, coding and programming; data communications, data conversion, and data analysis; architecture; planning; storage and retrieval; systems analysis and design; systems control; mobile applications; and equipment and services employed to collect, process, and present information to support the operation of an organization. The term also includes office automation, multimedia, telecommunications, and any personnel and support personnel required for planning and operations.
(14) Recodified as subdivision (a)(4a) at the direction of the Revisor of Statutes.
(13) Recodified as subdivision (a)(4a) at the direction of the Revisor of Statutes.
(15) Local government entity. — A local political subdivision of the State, including a city, a county, a local school administrative unit as defined in G.S. 115C-5, or a community college.
(14) Local government entity. — A local political subdivision of the State, including a city, a county, a local school administrative unit as defined in G.S. 115C-5, or a community college.
(16) Participating agency. — Any agency that has transferred its information technology personnel, operations, projects, assets, and funding to the Department of Information Technology. The State CIO shall be responsible for providing all required information technology support to participating agencies.
(15) Participating agency. — Any agency that has transferred its information technology personnel, operations, projects, assets, and funding to the Department of Information Technology. The State CIO shall be responsible for providing all required information technology support to participating agencies. (14a) Ransomware attack. — A cybersecurity incident where a malicious actor introduces software into an information system that encrypts data and renders the systems that rely on that data unusable, followed by a demand for a ransom payment in exchange for decryption of the affected data.
(17) Recodified as subdivision (a)(16a) at the direction of the Revisor of Statutes.
(16) Recodified as subdivision (a)(16a) at the direction of the Revisor of Statutes.
(18) Separate agency. — Any agency that has maintained responsibility for its information technology personnel, operations, projects, assets, and funding. The agency head shall work with the State CIO to ensure that the agency has all required information technology support.
(17) Separate agency. — Any agency that has maintained responsibility for its information technology personnel, operations, projects, assets, and funding. The agency head shall work with the State CIO to ensure that the agency has all required information technology support. (16a) Significant cybersecurity incident. — A cybersecurity incident that is likely to result in demonstrable harm to the State’s security interests, economy, critical infrastructure, or to the public confidence, civil liberties, or public health and safety of the residents of North Carolina. A significant cybersecurity incident is determined by the following factors: Incidents that meet thresholds identified by the Department jointly with the Department of Public Safety that involve information: That is not releasable to the public and that is restricted or highly restricted according to Statewide Data Classification and Handling Policy; or
(19) Significant cybersecurity incident. - A cybersecurity incident that is likely to result in demonstrable harm to the State's security interests, economy, critical infrastructure, or to the public confidence, civil liberties, or public health and safety of the residents of North Carolina. A significant cybersecurity incident is determined by the following factors: Incidents that meet thresholds identified by the Department jointly with the Department of Public Safety that involve information: That is not releasable to the public and that is restricted or highly restricted according to Statewide Data Classification and Handling Policy; or
(20) That involves the exfiltration, modification, deletion, or unauthorized access, or lack of availability to information or systems within certain parameters to include (i) a specific threshold of number of records or users affected as defined in G.S. 75-65 or (ii) any additional data types with required security controls.
(18) That involves the exfiltration, modification, deletion, or unauthorized access, or lack of availability to information or systems within certain parameters to include (i) a specific threshold of number of records or users affected as defined in G.S. 75-65 or (ii) any additional data types with required security controls.
(21) Incidents that involve information that is not recoverable or cannot be recovered within defined time lines required to meet operational commitments defined jointly by the State agency and the Department or can be recovered only through additional measures and has a high or medium functional impact to the mission of an agency.
(19) Incidents that involve information that is not recoverable or cannot be recovered within defined time lines required to meet operational commitments defined jointly by the State agency and the Department or can be recovered only through additional measures and has a high or medium functional impact to the mission of an agency.
(22) State agency or agency. — Any agency, department, institution, commission, committee, board, division, bureau, office, unit, officer, or official of the State. The term does not include the legislative or judicial branches of government or The University of North Carolina.
(20) State agency or agency. — Any agency, department, institution, commission, committee, board, division, bureau, office, unit, officer, or official of the State. The term does not include the legislative or judicial branches of government or The University of North Carolina.
(23) State Chief Information Officer or State CIO. — The head of the Department, who is a Governor’s cabinet level officer.
(21) State Chief Information Officer or State CIO. — The head of the Department, who is a Governor’s cabinet level officer.
(24) State CIO approved data center. — A data center designated by the State CIO for State agency use that meets operational standards established by the Department.
(22) State CIO approved data center. — A data center designated by the State CIO for State agency use that meets operational standards established by the Department.
(25) Exemptions. — Except as otherwise specifically provided by law, the provisions of this Chapter do not apply to the following entities: the General Assembly, the Judicial Department, and The University of North Carolina and its constituent institutions. These entities may elect to participate in the information technology programs, services, or contracts offered by the Department, including information technology procurement, in accordance with the statutes, policies, and rules of the Department. The election must be made in writing, as follows: For the General Assembly, by the Legislative Services Commission.
(23) Exemptions. — Except as otherwise specifically provided by law, the provisions of this Chapter do not apply to the following entities: the General Assembly, the Judicial Department, and The University of North Carolina and its constituent institutions. These entities may elect to participate in the information technology programs, services, or contracts offered by the Department, including information technology procurement, in accordance with the statutes, policies, and rules of the Department. The election must be made in writing, as follows: For the General Assembly, by the Legislative Services Commission.
(26) For the Judicial Department, by the Chief Justice.
(24) For the Judicial Department, by the Chief Justice.
(27) For The University of North Carolina, by the Board of Governors.
(25) For The University of North Carolina, by the Board of Governors.
(28) For the constituent institutions of The University of North Carolina, by the respective boards of trustees.
(26) For the constituent institutions of The University of North Carolina, by the respective boards of trustees.
(29) Deviations. — Any State agency may apply in writing to the State Chief Information Officer for approval to deviate from the provisions of this Chapter. If granted by the State Chief Information Officer, any deviation shall be consistent with available appropriations and shall be subject to such terms and conditions as may be specified by the State CIO.
(27) Deviations. — Any State agency may apply in writing to the State Chief Information Officer for approval to deviate from the provisions of this Chapter. If granted by the State Chief Information Officer, any deviation shall be consistent with available appropriations and shall be subject to such terms and conditions as may be specified by the State CIO.
(30) Review. — Notwithstanding subsection (b) of this section, any State agency shall review and evaluate any deviation authorized and shall, in consultation with the Department of Information Technology, adopt a plan to phase out any deviations that the State CIO determines to be unnecessary in carrying out functions and responsibilities unique to the agency having a deviation. The plan adopted by the agency shall include a strategy to coordinate its general information processing functions with the Department of Information Technology in the manner prescribed by this act and provide for its compliance with policies, procedures, and guidelines adopted by the Department of Information Technology. Any agency receiving a deviation shall submit its plan to the Office of State Budget and Management as directed by the State Chief Information Officer.
(28) Review. — Notwithstanding subsection (b) of this section, any State agency shall review and evaluate any deviation authorized and shall, in consultation with the Department of Information Technology, adopt a plan to phase out any deviations that the State CIO determines to be unnecessary in carrying out functions and responsibilities unique to the agency having a deviation. The plan adopted by the agency shall include a strategy to coordinate its general information processing functions with the Department of Information Technology in the manner prescribed by this act and provide for its compliance with policies, procedures, and guidelines adopted by the Department of Information Technology. Any agency receiving a deviation shall submit its plan to the Office of State Budget and Management as directed by the State Chief Information Officer.
History
(2015-241, s. 7A.2(b); 2019-200, s. 6(d).)
Enterprise Resource Planning (ERP) System. - Session Laws 2015-241, s. 7.22(a), provides: "In coordination with the Office of the State Controller (OSC) and the Office of State Budget and Management (OSBM), the Department of Information Technology (DIT) shall establish a program to plan, develop, and implement an enterprise resource planning (ERP) system for the State, including an investigation of the potential for a cloud-based unified ERP system."
Session Laws 2015-241, s. 7.22(b), provides: "During the 2015-2016 fiscal year, the DIT shall issue a request for information and coordinate demonstrations to determine available options for ERP system development and implementation. During the 2016-2017 fiscal year, subject to the availability of funding, the DIT shall issue requests for proposal to begin the development and implementation of an ERP system."
Session Laws 2015-241, s. 7.22(c), as amended by Session Laws 2016-94, s. 7.4(f), provides: "Beginning January 1, 2016, and semiannually thereafter, the DIT, in conjunction with OSC and OSBM, shall report to the Joint Legislative Oversight Committee on Information Technology and the Fiscal Research Division on the status of the program. The report shall include all of the following:
"(1) A detailed listing of current, completed, and potential future projects.
"(2) The amount of funding identified from restructuring savings since the inception of the program.
"(3) The uses of the identified funding.
"(4) The costs of current, completed, and potential future projects.
"(5) The status of planning and implementation of each project.
"(6) Identification of any issues associated with the program."
Session Laws 2016-94, s. 7.10, provides: "(a) The Department of Information Technology, in coordination with the Office of the State Controller and the Office of State Budget and Management, shall conduct the planning and design of an enterprise resource planning system (ERP) for State agencies by utilizing business process reengineering to identify and organize processes and workflow in order to prioritize and link work activities to realize efficiencies and organize around outcomes. The ERP system shall address, at a minimum, core financial management, grants, assets and inventory, fleet management, and human resource management. A request for proposal for a replacement system implementation shall be prepared for release no later than July 1, 2017. The Department may use savings generated through efficiencies gained from transition of participating agencies to the Department and overall Department operations, including procurement, to fund the project.
"(b) The Department of Information Technology shall submit a report to the Joint Legislative Oversight Committee on Information Technology on or before January 15, 2017. The report shall identify results from the business process reengineering efforts for State agencies and shall include at least all of the following:
"(1) Proposed sequence of functional and site implementation.
"(2) A phased-in contracting plan with checkpoints to facilitate budgeting and program management.
"(3) The feasibility of a cloud-based component.
"(4) Cost estimate for full implementation.
"(5) Detailed information relating to project funding from the savings generated through efficiencies gained from agency transition and overall Department operations."
Apprenticeships, and Career-Based Opportunities for Disabled Veterans. - Session Laws 2016-94, s. 7.7, as amended by Session Laws 2016-123, s. 3.1, provides: "(a) The Department of Information Technology shall create a cybersecurity apprenticeship program to provide training, apprenticeships, and career-based opportunities for disabled veterans within the State. Opportunities may be offered to qualifying veterans who have at least a ten percent (10%) disability rating as established by the United States Department of Veterans Affairs.
"(b) The State Chief Information Officer shall conduct a competitive process to select disabled veterans to participate in the cybersecurity apprenticeship program. Participants will have the opportunity to apply concepts, protocols, and tools acquired through the program by working side by side with experts in cybersecurity within the State of North Carolina.
"(c) Of the funds appropriated by this act for the support of the cybersecurity apprenticeship program, the Department of Information Technology shall select up to five disabled veterans to participate in the program. The Department may use funds generated from receipts for continuation or expansion of the program beyond the 2016-2017 fiscal year."

Official source: North Carolina General Assembly. Reproduced from public-domain North Carolina statutes; confirm against the official source for the current text. Not legal advice.